Analytics Informational

Abnormal connections to a dormant host from a newly seen endpoint

The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Remote System Discovery (T1018)
Attacker's goals:

While probing the network, an attacker may discover dormant hosts. These inactive systems can then be used for lateral movement or privilege escalation.

Investigative actions:

Validate that the source is not a sanctioned port scanner. Check for suspicious artifacts in the endpoint profile.

Test period:
6 Hours
Deduplication:
1 Day
1 variation:
  • Abnormal connections to a dormant host Low (parent: Informational)